#!/usr/bin/env bash # Restore a backup into a disposable PostgreSQL 16 cluster with no TCP listener. set -euo pipefail umask 077 [[ $EUID == 0 && $# == 1 ]] || exit 64 snapshot=$(readlink -f "$1") [[ -f $snapshot/COMPLETE && -f $snapshot/k3s.dump ]] || exit 66 (cd "$snapshot"; sha256sum --quiet -c SHA256SUMS) bin=/usr/lib/postgresql/16/bin stage=$(mktemp -d /var/tmp/atlas-k3s-restore.XXXXXXXX) started=$(date +%s) cleanup() { if [[ -f $stage/data/postmaster.pid ]]; then runuser -u postgres -- "$bin/pg_ctl" -D "$stage/data" -m immediate -w stop >/dev/null 2>&1 || true fi rm -rf -- "$stage" } trap cleanup EXIT chown postgres:postgres "$stage" install -o postgres -g postgres -m 0600 "$snapshot/k3s.dump" "$stage/k3s.dump" exec 2>"$snapshot/restore-error.txt" runuser -u postgres -- "$bin/initdb" -D "$stage/data" -A trust --no-locale >"$stage/init.log" runuser -u postgres -- "$bin/pg_ctl" -D "$stage/data" -l "$stage/server.log" \ -o "-k $stage -p 55432 -c listen_addresses=''" -w start >/dev/null runuser -u postgres -- "$bin/createdb" -h "$stage" -p 55432 k3s timeout 900 runuser -u postgres -- "$bin/pg_restore" --exit-on-error --no-owner --no-privileges \ -h "$stage" -p 55432 -d k3s "$stage/k3s.dump" rows=$(runuser -u postgres -- "$bin/psql" -XAt -h "$stage" -p 55432 -d k3s -c 'SELECT count(*) FROM kine') [[ $rows =~ ^[0-9]+$ && $rows -gt 0 ]] printf 'verified_utc=%s\nelapsed_seconds=%s\nkine_rows=%s\nmethod=isolated_pg16_restore_without_role_acl_replay\n' \ "$(date -u +%FT%TZ)" "$(( $(date +%s) - started ))" "$rows" >"$snapshot/RESTORE_CHECK" cat "$snapshot/RESTORE_CHECK"